CCSP Cloud Application Security Practice Question
A cloud-native payroll application stores employee bank details in a managed database. The security team wants to ensure that even if the database storage is compromised, the data cannot be read without explicit decryption. They also need to minimize changes to the application code. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is treating any encryption at rest as sufficient, when the decisive factor is who controls the keys and when decryption occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement client-side field-level encryption using a customer-managed key (CMK) in a cloud KMS.
The team needs encryption where keys are controlled by the organization and decryption is explicit, not automatic. Client-side field-level encryption with a customer-managed key in a cloud KMS achieves this: ciphertext is stored in the database, and only holders of the CMK can decrypt. TDE, provider-managed keys, and database-native encryption with locally stored keys all leave decryption capability with the database or provider, failing the threat model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use database-native column encryption with keys stored in the database configuration.
Why it's wrong here
Column encryption protects data at rest, but storing keys in the database configuration means anyone with database or configuration access can decrypt. It does not separate key custody from the data store, so a storage compromise could expose both ciphertext and keys. This fails the requirement for explicit decryption control.
- ✗
Enable transparent data encryption (TDE) at the database storage layer using provider-managed keys.
Why it's wrong here
TDE encrypts data at rest but the database engine decrypts it transparently for any query, and provider-managed keys mean the provider can also decrypt. If the storage is compromised, an attacker with database access or provider cooperation can read plaintext. It does not provide the explicit decryption control or separation the team requires.
- ✓
Implement client-side field-level encryption using a customer-managed key (CMK) in a cloud KMS.
Why this is correct
Client-side field-level encryption encrypts sensitive fields before they reach the database, so stored ciphertext is useless without the CMK. Using a customer-managed key in a cloud KMS keeps key control with the organization and enables explicit decryption. The application performs encryption and decryption, which is a code change but targeted to specific fields, meeting both requirements.
- ✗
Rely on the cloud provider's default encryption at rest with provider-managed keys.
Why it's wrong here
Default provider-managed encryption at rest protects against physical disk theft but not against logical compromise or insider access through the provider. The provider holds the keys, so the organization cannot enforce explicit decryption. This does not meet the requirement that data remain unreadable even if the database storage is compromised.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.